{"apiVersion":"1.0","identifier":"CVE-2026-80724","description":"In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the page read-only and then upgrade it to writable with mprotect(), after which the guest can corrupt the host-written timekeeping data (sequence counter, UTC time, TSC offset) that the vmclock ABI defines as read-only. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 does for its read-only objects and as fixed in drm/vc4 (CVE-2026-68445) and drm/panthor (CVE-2024-53071).","publishedAt":"2026-08-28T08:16:58","lastModifiedAt":"2026-08-28T08:16:58","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80724","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00154,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80724","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80724","en":"https://www.redsauce.net/en/cves/CVE-2026-80724","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80724","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80724","de":"https://www.redsauce.net/de/cves/CVE-2026-80724","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80724","el":"https://www.redsauce.net/el/cves/CVE-2026-80724"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80724"}}